Security
Your resume, protected.
Every technical and operational choice we've made to keep your data safe.
Encryption
- At rest: AES-256 on our managed database (MongoDB Atlas) and object storage (Cloudflare R2), with per-environment credentials.
- In transit: TLS 1.3 on every edge; HSTS; no plaintext fallbacks.
Isolation
- Sign-in and sessions are handled by Clerk; every backend request is verified against your signed session token before any data is read.
- Per-user data is partitioned by user ID at the query layer — cross-user reads are rejected structurally, not by an afterthought check.
- No long-lived cloud credentials in code: secrets live in the hosting platform's environment store and rotate on change.
AI model providers
- Matching and auto-apply are powered by frontier models accessed under no-training API terms — your data is not used to train anyone's models.
- Your resume and profile details are sent to a model provider only to power features you invoke — scoring your fit for a job, or filling an application you approved. They are never sold, shared for advertising, or used for anything else.
- Analytics and telemetry are PII-stripped before they leave the request path — names, emails, and resume text never enter our analytics tooling.
Compliance
- SOC 2 Type I — engaged, targeting 2026 Q3.
- GDPR — data subject access, portability, and deletion implemented.
- CCPA / CPRA — request portal at /legal/ccpa/.
- DPA for B2B at /legal/dpa/.
Responsible disclosure
We run a private disclosure program. Email security@jobeezy.com with details (PGP-encrypted preferred). We acknowledge within 24 hours and fix critical issues within 7 days. Public disclosure welcome after a fix ships.
Incident history
No security incidents disclosed. We will update this page within 72 hours of detection of any qualifying event.